CVE Explorer.
Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.
404,367 CVEs
1,739 on KEV
17,299 EPSS ≥ 10%
25,091 with exploits
synced 2026-10-11
25,091 results
| CVE | Summary | Priority | CVSS | EPSS | Published |
|---|---|---|---|---|---|
| CVE-2013-7136 EXP | The UPC Ireland Cisco EPC 2425 router (aka Horizon Box) does not have a sufficiently large number of possible WPA-PSK passphrases, which makes it easi… | Patch early | 9.3 high | 6.5% | 2013-12-19 |
| CVE-2010-2375 EXP | Package/Privilege: Plugins for Apache, Sun and IIS web servers Unspecified vulnerability in the WebLogic Server component in Oracle Fusion Middleware… | Patch early | 6.4 medium | 6.5% | 2010-07-13 |
| CVE-2006-0586 EXP | Multiple SQL injection vulnerabilities in Oracle 10g Release 1 before CPU Jan 2006 allow remote attackers to execute arbitrary SQL commands via multip… | Patch early | 7.5 high | 6.5% | 2006-02-08 |
| CVE-2009-2015 EXP | Directory traversal vulnerability in includes/file_includer.php in the Ideal MooFAQ (com_moofaq) component 1.0 for Joomla! allows remote attackers to… | Patch early | 7.5 high | 6.5% | 2009-06-09 |
| CVE-2012-5318 EXP | Unrestricted file upload vulnerability in uploadify/scripts/uploadify.php in the Kish Guest Posting plugin 1.2 for WordPress allows remote attackers t… | Patch early | 6.8 medium | 6.5% | 2012-10-08 |
| CVE-2012-5335 EXP | Directory traversal vulnerability in Tiny Server 1.1.5 allows remote authenticated users to read arbitrary files via a .. (dot dot) in the URI of an H… | Patch early | 4.0 medium | 6.5% | 2012-10-08 |
| CVE-2007-5320 EXP | Multiple absolute path traversal vulnerabilities in Pegasus Imaging ImagXpress 8.0 allow remote attackers to (1) delete arbitrary files via the CacheF… | Patch early | 4.0 medium | 6.5% | 2007-10-09 |
| CVE-2006-5758 EXP | The Graphics Rendering Engine in Microsoft Windows 2000 through 2000 SP4 and Windows XP through SP2 maps GDI Kernel structures on a global shared memo… | Patch early | 7.2 high | 6.5% | 2006-11-06 |
| CVE-2007-1251 EXP | Format string vulnerability in the new_warning function in ntserv/warning.c for Netrek Vanilla Server 2.12.0, when EVENTLOG is enabled, allows remote… | Patch early | 9.3 high | 6.5% | 2007-03-03 |
| CVE-2007-2483 EXP | Directory traversal vulnerability in js/wptable-button.php in the wp-Table 1.43 and earlier plugin for WordPress, when register_globals is enabled, al… | Patch early | 6.8 medium | 6.5% | 2007-05-03 |
| CVE-2002-1001 EXP | Buffer overflows in AnalogX Proxy before 4.12 allows remote attackers to cause a denial of service and possibly execute arbitrary code via (1) a long… | Patch early | 7.5 high | 6.5% | 2002-10-04 |
| CVE-2006-0304 EXP | Buffer overflow in Dual DHCP DNS Server 1.0 allows remote attackers to cause a denial of service (application crash) and possibly execute arbitrary co… | Patch early | 7.5 high | 6.5% | 2006-01-19 |
| CVE-2019-10963 EXP | Moxa EDR 810, all versions 5.1 and prior, allows an unauthenticated attacker to be able to retrieve some log files from the device, which may allow se… | Patch early | 4.3 medium | 6.5% | 2019-10-08 |
| CVE-2018-4367 EXP | A memory corruption issue was addressed with improved input validation. This issue affected versions prior to iOS 12.1. | Patch early | 9.8 critical | 6.5% | 2019-04-03 |
| CVE-2016-10079 EXP | SAPlpd through 7400.3.11.33 in SAP GUI 7.40 on Windows has a Denial of Service vulnerability (service crash) with a long string to TCP port 515. | Patch early | 7.5 high | 6.5% | 2017-02-01 |
| CVE-2002-0206 EXP | index.php in Francisco Burzi PHP-Nuke 5.3.1 and earlier, and possibly other versions before 5.5, allows remote attackers to execute arbitrary PHP code… | Patch early | 7.5 high | 6.5% | 2002-05-16 |
| CVE-2012-6653 EXP | Unspecified vulnerability in the All Video Gallery (all-video-gallery) plugin before 1.2.0 for WordPress has unspecified impact and attack vectors. | Patch early | 7.5 high | 6.5% | 2014-08-06 |
| CVE-2009-4142 EXP | The htmlspecialchars function in PHP before 5.2.12 does not properly handle (1) overlong UTF-8 sequences, (2) invalid Shift_JIS sequences, and (3) inv… | Patch early | 4.3 medium | 6.5% | 2009-12-21 |
| CVE-2016-1910 EXP | The User Management Engine (UME) in SAP NetWeaver 7.4 allows attackers to decrypt unspecified data via unknown vectors, aka SAP Security Note 2191290. | Patch early | 5.3 medium | 6.5% | 2016-01-15 |
| CVE-2013-2624 EXP | Telean before 1.3.1 contains a full path disclosure vulnerability which could allow remote attackers to obtain sensitive information through a special… | Patch early | 5.3 medium | 6.5% | 2020-02-03 |
| CVE-2007-2832 EXP | Cross-site scripting (XSS) vulnerability in the web application firewall in Cisco CallManager before 3.3(5)sr3, 4.1 before 4.1(3)sr5, 4.2 before 4.2(3… | Patch early | 4.3 medium | 6.5% | 2007-05-24 |
| CVE-2015-6995 EXP | The Disk Images component in Apple iOS before 9.1 and OS X before 10.11.1 misparses images, which allows attackers to execute arbitrary code or cause… | Patch early | 6.8 medium | 6.5% | 2015-10-23 |
| CVE-2001-1290 EXP | admin.cgi in Active Classifieds Free Edition 1.0, and possibly commercial versions, allows remote attackers to modify the configuration, gain privileg… | Patch early | 5.0 medium | 6.5% | 2001-06-28 |
| CVE-2018-4386 EXP | Multiple memory corruption issues were addressed with improved memory handling. This issue affected versions prior to iOS 12.1, tvOS 12.1, watchOS 5.1… | Patch early | 8.8 high | 6.5% | 2019-04-03 |
| CVE-2011-3336 EXP | regcomp in the BSD implementation of libc is vulnerable to denial of service due to stack exhaustion. | Patch early | 7.5 high | 6.5% | 2020-02-12 |
| CVE-2004-2677 EXP | Format string vulnerability in qwik-smtpd.c in QwikMail SMTP (qwik-smtpd) 0.3 and earlier allows remote attackers to execute arbitrary code via format… | Patch early | 7.5 high | 6.5% | 2004-12-31 |
| CVE-2011-5166 EXP | Multiple stack-based buffer overflows in KnFTP 1.0.0 allow remote attackers to execute arbitrary code via a long string to the (1) USER, (2) PASS, (3)… | Patch early | 7.5 high | 6.5% | 2012-09-15 |
| CVE-2001-0466 EXP | Directory traversal vulnerability in ustorekeeper 1.61 allows remote attackers to read arbitrary files via a .. (dot dot) in the file parameter. | Patch early | 5.0 medium | 6.5% | 2001-06-18 |
| CVE-2022-3766 EXP | Cross-site Scripting (XSS) - Reflected in GitHub repository thorsten/phpmyfaq prior to 3.1.8. | Patch early | 6.1 medium | 6.5% | 2022-10-31 |
| CVE-2001-0075 EXP | Directory traversal vulnerability in main.cgi in Technote allows remote attackers to read arbitrary files via a .. (dot dot) attack in the filename pa… | Patch early | 5.0 medium | 6.5% | 2001-02-12 |
How to read it
Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.
Watch your own stack → and get told only when something that matters to it moves.
→ all tools · exposure · dns · email · headers · tls · ct · cookies · reputation · security.txt